DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
The Identity Gap in Agentic AI

The Identity Gap in Agentic AI

Comments
4 min read
User Enumeration: How One Leaky Error Message Lets Attackers Find Valid Usernames and Crack Your Passwords

User Enumeration: How One Leaky Error Message Lets Attackers Find Valid Usernames and Crack Your Passwords

Comments
3 min read
Hardening an Express API: URL Validation, Error Handling, and Tests in One Session

Hardening an Express API: URL Validation, Error Handling, and Tests in One Session

Comments
2 min read
I Ran My ML Secrets Detector Against My Own Repositories — Here's What It Found

I Ran My ML Secrets Detector Against My Own Repositories — Here's What It Found

Comments
10 min read
Gmail OAuth client_id is not a secret â design notes for self-host Actors

Gmail OAuth client_id is not a secret â design notes for self-host Actors

Comments
5 min read
APPROVED_SPENDERS Policy: Control Which Contracts Your AI Agent Can Approve

APPROVED_SPENDERS Policy: Control Which Contracts Your AI Agent Can Approve

Comments
4 min read
AI Agents Are Your Enterprise's Newest Security Blind Spot

AI Agents Are Your Enterprise's Newest Security Blind Spot

Comments
4 min read
The Compliance Case for Machine Identity

The Compliance Case for Machine Identity

Comments
4 min read
Automated Advanced Analytics: An Unexpected Tool in the Cyber Arsenal

Automated Advanced Analytics: An Unexpected Tool in the Cyber Arsenal

Comments 1
2 min read
Building HIPAA-Compliant Healthcare Software: Lessons from PSI Nest

Building HIPAA-Compliant Healthcare Software: Lessons from PSI Nest

Comments
2 min read
AI & Supply Chain Security: Prompt Injection Suite, Nginx CVE, & Rockstar Breach

AI & Supply Chain Security: Prompt Injection Suite, Nginx CVE, & Rockstar Breach

Comments
3 min read
How I Built a 3-Tier Approval Engine with Spring Boot and Spring Security

How I Built a 3-Tier Approval Engine with Spring Boot and Spring Security

1
Comments 1
5 min read
When a Git Branch Name Becomes a Weapon: The Codex Command Injection That Could Steal Your GitHub Token

When a Git Branch Name Becomes a Weapon: The Codex Command Injection That Could Steal Your GitHub Token

Comments
6 min read
Multi-Tenant AI Agent Architectures: Isolation, Routing, and Data Safety

Multi-Tenant AI Agent Architectures: Isolation, Routing, and Data Safety

1
Comments
13 min read
Why AI coding agents keep making the same mistakes (and how to stop it)

Why AI coding agents keep making the same mistakes (and how to stop it)

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.